PT-2026-21283 · Unknown · Fiverr Clone Script
Mr Winst0N
·
Publicado
2026-02-20
·
Atualizado
2026-02-20
·
CVE-2019-25444
CVSS v3.1
9.1
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Fiverr Clone Script version 1.2.2
Description
The software contains an SQL injection issue that allows unauthenticated attackers to manipulate database queries. Attackers can inject SQL code through the
page parameter to extract sensitive database information or modify database contents. The affected API endpoint is not specified. The vulnerable parameter is page.Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the
page parameter.Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Fiverr Clone Script